ResearchPod Summary
As regulatory frameworks like the EU AI Act mandate the identification of AI-generated content, existing watermarking techniques face significant practical hurdles. Current methods often require access to the original language model (LM) for detection, lack a closed-form mathematical relationship between regulatory targets (such as false-positive rates) and configuration parameters, and exhibit poor robustness against common text-editing attacks like back-translation.
ChainMark introduces an active, model-free watermarking scheme. It uses a secret key and a SHA-256 hash to partition the model's vocabulary into S states arranged in a cycle. During generation, the model is constrained to follow this cycle at a specific fraction of positions (the watermark budget). Because the state transitions are deterministic based on the key, a verifier can detect the watermark by re-deriving the state sequence from the text alone in O(n) time, without needing the generating model.
ChainMark provides a closed-form mapping that allows regulators to set a target false-positive rate (FPR), text-length floor, and budget, which then dictates the required state count. The authors prove a universal robustness threshold of approximately 29.3% against random token substitution, which is invariant to the watermark's configuration. In head-to-head experiments across three instruction-tuned LLMs, ChainMark significantly outperforms KGW and SWEET in true-positive rates after Chinese back-translation (72.8% vs. <20%), while maintaining comparable performance on clean text. The authors also provide a one-corpus recalibration method to ensure the target FPR is strictly met on natural language.
By decoupling the detection process from the language model, ChainMark enables third-party auditing of AI-generated content, a key requirement for compliance with emerging AI governance regulations. Its ability to map policy-level requirements directly to technical configurations provides a transparent and predictable framework for deployers and regulators alike.
AI-generated third-party summary by ResearchPod. Not official content or an endorsement by the paper authors or affiliated organizations.